RHSA-2025:1869HighCVSS 8.1

Red Hat Security Advisory: Red Hat OpenStack Platform 16.2 (osp-director-operator) security update

Published
February 26, 2025
Last Modified
August 15, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2025-21613 — go-git: argument injection via the URL field CVE-2025-21614 — go-git: go-git clients vulnerable to DoS via maliciously crafted Git server replies

🎯 Affected products5

  • Red Hat OpenStack Platform 16.2
  • rhosp-rhel8/osp-director-agent@sha256:2732885be77c420c09d4b193256f98f791fbaf68b0df53ce74a075312d5909be_amd64 as a component of Red Hat OpenStack Platform 16.2
  • rhosp-rhel8/osp-director-downloader@sha256:d2a3d5f1197063fdfe3243eaf9ecb599e77201a06a589b9021845e4fd1d3473c_amd64 as a component of Red Hat OpenStack Platform 16.2
  • rhosp-rhel8/osp-director-operator-bundle@sha256:65acbffc986354da1ce64aff2f02fb32b91a307852317b50516adc19f2c75c6e_amd64 as a component of Red Hat OpenStack Platform 16.2
  • rhosp-rhel8/osp-director-operator@sha256:f688739a10ab007f7a8a0de75327d56a67a9da1182d9a06130d75e0b57617da9_amd64 as a component of Red Hat OpenStack Platform 16.2

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: In cases where it is not possible to update to the latest version of go-git, it is recommended to enforce validation rules for values passed in the URL field.

🔗 References (5)